Twilio incident: What Signal users need to know
61–70 of 512 posts
Re: Twilio incident: What Signal users need to know
#62I wonder how many other companies have been successfully phished that we don't know about.
Re: Twilio incident: What Signal users need to know
#63Earlier quoted context omitted.
That's a good way to build a secure messaging app nobody ever uses.
It may very well be the case for the smartphone-flipping demographic that prefer WhatsApp and TikTok, but I think it's a misunderstanding/misrepresentation of the crowd that go for e.g. Signal and Telegram.
Re: Twilio incident: What Signal users need to know
#64These attacks are sophisticated and are capable of bypassing TOTP or mobile-app-based MFA. If this is widespread, I’d be surprised if we didn’t see a massive influx of breaches soon. The vast majority of companies are not well defended against this.
Re: Twilio incident: What Signal users need to know
#65Earlier quoted context omitted.
Signal doesn't ask for phone numbers simply to combat spam; the phone number isn't an elaborate captcha. Rather, as this article repeatedly points out, Signal doesn't keep your contact lists and other data available to its servers. It uses phone numbers because phones already have contact lists, stored clientside, keyed by those numbers. To replace the numbers with usernames, Signal users would have to either give up…
Users having to add their contacts each time they set Signal up on a new phone, should the app keep its own client-side contact book, doesn't sound like hassle. Could you please explain how Signal does not have a social network map, when 1) user accounts are equal to mobile phone numbers, and 2) Signal servers route messages between user accounts.
Even if Signal's server saves a message (they claim not to, once downloaded), Signal's server by design has no way of knowing who sent the message.
Re: Twilio incident: What Signal users need to know
#66Earlier quoted context omitted.
You forgot the part where joining signal "conveniently" discloses that to everyone - with no way to opt out(!). Also, everyone not sharing their contacts with the signal app already have that UX. Minus the privacy benefits of course.
Signal has always prioritized message security and integrity over anonymity. If you want anonymity, Signal is not, has not, and probably never will be the tool for you.
Re: Twilio incident: What Signal users need to know
#67Earlier quoted context omitted.
Give people the option to pay. I would gladly pay $100 one time fee if it meant I could avoid having a phone number associated. https://jmp.chat is a great work around but I would rather just have an email address or ideally nothing but a receipt directly associated with my signal account.
Isn't email even worse for security?
I just want to be able to communicate without sharing my phone number (since my phone number is bound to Swedish "Swish") meaning someone can get my ID from my phone number here.
This is why drug dealers use Wickr, Threema and others, because they don't expose identity, not because they're "safer".
I have a contact on Threema who I've met many times, but I have no idea how to contact him outside of Threema, because I don't know his identity and we'd both like to keep it that way.
Re: Twilio incident: What Signal users need to know
#68Please, stop using phone numbers. There is no reliable way to hold a phone number. The messaging protocols are insecure. If your service uses phone numbers or SMS, that means it's not secure or reliable.
Not only that, I don't want any service that I use tied to a phone number. Partially for the reasons you listed, but also because there are better alternatives; email, authenticator apps, physical keys, cards, etc. I hate looking at my phone. I hate using my phone. I don't want to have even more reasons to keep my phone charged and in my hand. Phones suck.
Re: Twilio incident: What Signal users need to know
#69Earlier quoted context omitted.
I've been complaining about the glaring privacy/integrity problem in their SMS-based account verification scheme for years. I don't think any snafu can make them reconsider. It would forfeit the valuable social network mapping they've already poured millions of dollars into through sending verification SMSes.
It's not so much "valuable social network mapping" as it is "the only social network available to Signal", by design. Without phone numbers, they can't use clientside contact lists (they can build their own, of course, but if it's strictly clientside it won't sync, and so it won't work for most of their users). The alternative design, which HN would wildly prefer, admits to usernames or email address accounts, but re…
Re: Twilio incident: What Signal users need to know
#70Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.